I think the answer is C. It just makes the most sense to me. I mean, what's the point of having a correlation rule if it doesn't do anything when it's triggered? You'd have to be a real 'network traffic' to think otherwise.
This is a tricky one. I was tempted to choose B, but blocking the network traffic doesn't seem like the right response. I'm gonna go with C, just to be on the safe side.
Hmm, I'm not sure. I'm leaning towards D, but I could be wrong. An event being logged to the Correlation Policy Management table does seem like a logical outcome.
I think C is the correct answer. The Defense Center should generate a correlation event and initiate any configured responses when the network traffic meets the criteria specified in the correlation rule.
Joanna
11 months agoFletcher
10 months agoNorah
10 months agoLanie
10 months agoRuby
10 months agoOdette
11 months agoJutta
10 months agoLeah
10 months agoHannah
10 months agoKendra
11 months agoJose
11 months agoGlory
11 months agoSherell
11 months agoWillow
11 months agoVeronique
11 months agoAlpha
11 months agoEladia
11 months agoBen
11 months agoZoila
10 months agoWynell
10 months agoShannan
11 months agoMari
11 months agoHeike
12 months ago